X-suite Messages

Vendor Documentation


Classification

Rule Name

Rule Type

Common Event

Classification

X-suite Messages

Base Rule

General Information

Information

Connection Successful Messages

Sub Rule

Connection Built

Network Traffic

Connection Closed Messages

Sub Rule

Connection Closed

Network Traffic

Connection Timeout Messages

Sub Rule

Connection Timed Out

Network Traffic

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

severity

<severity>

Text/String

processid

<processid>

Number

Source IP

<sip>

IP Address

Nat/Proxy IP

<snatip>

IP Address

User

<login>

Text/String

Address

<dip>

IP Address

Device name

<sname>

Text/String

subject

<subject>

Text/String

Port

<dport>

Number

Access/Protocol

<protname>

Text/String

Service/App

<object>

Text/String

Details

<status>

Text/String

Details

<tag1>

Text/String

minutes

<minutes>

Number